Case study
A French venture capital firm attached to a banking group, this investment structure backs innovative companies at their various stages of development. Recently separated from its parent group's information system, it must nonetheless stay compliant with the group's security arrangements and requirements.
The internal risk and compliance team is deliberately small, and its head also serves as CISO. The firm wants to set up and then run, over time, a cybersecurity framework structured around the NIST standard.
A consultant specialising in cybersecurity for the financial sector is mobilised on a recurring basis, two days a week on average, with the workload flexed around activity peaks. He runs the set-up day to day without touching operations: maintaining the level required by the NIST framework and the parent group, coordinating with the group's teams and the vendors, handling day-to-day requests and continuously improving the steering.
Company profile